NGO makes their living because neither of those have back doors. They come up with very complicated exploit chains because the easy attacks are no longer possible.
Android and iOS both have backdoors the US controls. The few capabilities they aren't willingly given by Apple or Google are furnished by third-parties, and the rest of the world has to contend with second-rate data access through persistent exploits. If the US didn't have superior SigInt, they'd be relying on Pegasus to do FIVE-EYES' dirty work. Google and Apple both admit that their information handling is overseen and controlled by the US federal government: https://www.reuters.com/technology/cybersecurity/governments...
> They come up with very complicated exploit chains because the easy attacks are no longer possible.
People say this about every age of computing, though. And then we get a zero-click exploit chain from Pakistan with persistent payload that infects 22,000 modern handsets for 3 months without anyone knowing. I don't think that complexity is the secure savior you make it out to be in this situation.